Last updated August 5, 2026
Privacy Policy
This policy explains what information Aleen collects, why we need it, who processes it, and the choices you have. Our separate Consumer Health Data Notice provides additional detail about health data.
1. Who we are and the scope of this policy
Aleen is a personalized fitness and nutrition coaching application for adults operated by KobasLabs LLC, a Delaware limited liability company in the United States. In this policy, “Aleen,” “we,” “us,” and “our” refer to KobasLabs LLC as operator of the Aleen mobile app and aleen.fit.
This policy applies to the Aleen mobile app, our website, support, and related services in the United States. Aleen is not a healthcare provider and is not a HIPAA-covered medical service.
Contact us at privacy@aleen.fit, +1 617 602 8027, or KobasLabs LLC, 2093 Philadelphia Pike, Claymont, Delaware 19703, United States.
2. Information we collect
- Account and authentication: name, email address, account identifier, sign-in provider, and login/security metadata. Passwords are handled by our authentication provider; we do not receive them in readable form.
- Profile and body information: age, height, weight, goal weight, units, time zone, goals, experience, equipment, schedule, and preferences.
- Consumer health data you choose to provide: health conditions, GLP-1 or other weight-management medication status, pregnancy, postpartum and breastfeeding status, cycle information, symptoms, sleep, stress, injuries, restrictions, and free-text health details.
- Fitness and nutrition activity: plans, exercises, sets, repetitions, weights, completed or missed sessions, swaps and reschedules, meal choices and logs, dietary preferences, avoided foods, and check-ins.
- Coach communications: messages you send to the coach, its replies, confirmed profile updates, and safety classifications.
- Derived information: estimates and inferences such as energy and macro targets, BMI, training volume, adherence, e1RM and personal-record estimates, recovery mode, cycle phase, progress trends, and plan adjustments.
- Device and service data: IP address, device/platform information, app version, timestamps, crash/security logs, and a notification token if you enable notifications.
- Purchases: if paid subscriptions are offered, subscription status and store transaction identifiers from Apple or Google. We do not receive full payment-card numbers.
- Launch list and website attribution: if you join the launch list, we collect your email address and may record browser locale, referring website host, and UTM campaign fields. The launch form does not collect health, medication, workout, or nutrition information.
At present, the Aleen mobile app does not request photos, contacts, microphone/audio, precise location, HealthKit, Health Connect, or advertising identifiers.
3. How we use information
- create, display, and adapt your training and nutrition plan;
- provide the coach, progress, reminders, check-ins, safety screening, and account support;
- authenticate users, prevent abuse, debug failures, audit plan quality, and secure the service;
- meet legal obligations, enforce our Terms, and investigate incidents; and
- improve product reliability using aggregated or de-identified analysis where practical.
We do not sell personal or consumer health data. We do not use health data for targeted advertising.
4. AI processing
Aleen’s deterministic engines create the core plan. An AI provider is used for coach conversations, safety classification, and a structured internal plan review. A coach request can include your message, relevant profile and health context, current plan, recent training and weight history, and recent chat history so that the reply is contextual.
Our commercial AI provider is Anthropic. Under its commercial API terms, API inputs and outputs are not used to train its models by default. Standard API data is generally retained for up to 30 days, subject to limited safety, legal, or separately agreed exceptions. Internal plan-review output does not reach you directly; deterministic safety checks and plan rules remain authoritative.
AI can be wrong. Aleen prohibits medical diagnosis, treatment, medication instructions, and emergency reassurance. See our Safety & Medical Boundary.
5. When information is disclosed
We disclose only what is needed to service providers acting for us:
- Supabase for authentication, database, and storage infrastructure;
- Railway for API hosting and operational logs;
- Anthropic for the limited AI processing described above;
- Expo and operating-system providers for notifications and app delivery; and
- Apple and Google if you use their sign-in or app-store services;
- Vercel for the public website and its operational security; and
- Resend for transactional and launch-list email delivery.
These providers are limited to the information required for their role and must protect it under applicable contractual and security safeguards. We may also disclose information if required by law, to protect people or the service from serious harm or fraud, or in a business transaction subject to appropriate safeguards and notice. We do not disclose health data to data brokers or advertising networks.
6. Retention and deletion
We retain account, plan, activity, and coach data while your account is active because it powers longitudinal personalization. When you delete your account, Aleen deletes the account and associated active-service data, including profiles, plans, logs, messages, and notification tokens. Deletion does not automatically cancel a subscription managed by an app store.
Service-provider logs and AI requests follow the providers’ limited operational retention schedules. Data isolated in backups is not used for ordinary processing and is deleted as backups expire, and no later than six months after a verified deletion request where consumer-health law requires that deadline. We may retain a minimal record if law requires it or to establish that a request was completed.
Launch-list data is kept until the launch message is sent, you ask to leave the list, or the list is retired. Every marketing or launch email will provide a way to unsubscribe. You may also leave the list by emailing privacy@aleen.fit.
7. Your choices and rights
- access and correct information through the app or a verified request;
- withdraw consumer-health-data consent in Settings, which stops future health-data processing and removes notification tokens;
- delete your account in Settings or follow the instructions on our Delete Account page;
- request access, correction, deletion, a list of relevant third parties, or appeal a denied request by emailing privacy@aleen.fit.
We verify requests to protect the account. We generally respond within 45 days and explain any permitted extension or denial. Authorized agents may submit requests where applicable, subject to verification.
8. Security, age, and changes
We use access controls, private databases, encrypted network connections, service-role isolation, and monitoring appropriate to the sensitivity of the information. No system can guarantee absolute security. If a breach triggers notice duties, we will provide required notices.
Aleen is for adults aged 18 and older. We do not knowingly collect personal information from children.
We may update this policy. We will change the date above and, when a material change affects consent or health-data use, provide prominent notice and request new consent where required.
9. Contact
Privacy questions or requests: privacy@aleen.fit. Product support: support@aleen.fit.
KobasLabs LLC, 2093 Philadelphia Pike, Claymont, Delaware 19703, United States · +1 617 602 8027.